2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41931 | CRITICAL | 9.8 | 1.3% | Nov 17, 2021 | The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnera... |
| CVE-2021-32600 | LOW | 3.8 | 0.6% | Nov 17, 2021 | An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6... |
| CVE-2021-24856 | MEDIUM | 4.8 | 0.6% | Nov 17, 2021 | The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which c... |
| CVE-2021-24854 | MEDIUM | 5.4 | 0.6% | Nov 17, 2021 | The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could... |
| CVE-2021-24853 | MEDIUM | 4.3 | 0.4% | Nov 17, 2021 | The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector se... |
| CVE-2021-24852 | MEDIUM | 6.5 | 0.5% | Nov 17, 2021 | The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which c... |
| CVE-2021-24851 | MEDIUM | 4.3 | 0.9% | Nov 17, 2021 | The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and meta... |
| CVE-2021-24850 | MEDIUM | 5.4 | 0.6% | Nov 17, 2021 | The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. ... |
| CVE-2021-24847 | HIGH | 8.8 | 1.3% | Nov 17, 2021 | The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, ... |
| CVE-2021-24841 | MEDIUM | 4.8 | 0.7% | Nov 17, 2021 | The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2021-24834 | MEDIUM | 5.4 | 1.5% | Nov 17, 2021 | The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in th... |
| CVE-2021-24833 | MEDIUM | 5.4 | 1.1% | Nov 17, 2021 | The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in t... |
| CVE-2021-24815 | MEDIUM | 4.8 | 0.6% | Nov 17, 2021 | The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created But... |
| CVE-2021-24804 | HIGH | 8.8 | 0.6% | Nov 17, 2021 | The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attacke... |
| CVE-2021-24802 | MEDIUM | 6.5 | 0.5% | Nov 17, 2021 | The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make... |
| CVE-2021-24796 | MEDIUM | 6.1 | 1.2% | Nov 17, 2021 | The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets be... |
| CVE-2021-24787 | MEDIUM | 4.8 | 0.6% | Nov 17, 2021 | The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings... |
| CVE-2021-24776 | MEDIUM | 4.3 | 0.4% | Nov 17, 2021 | The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which co... |
| CVE-2021-24772 | HIGH | 8.8 | 1.5% | Nov 17, 2021 | The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records ... |
| CVE-2021-24758 | HIGH | 8.8 | 1.3% | Nov 17, 2021 | The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GE... |
| CVE-2021-24598 | MEDIUM | 4.8 | 0.7% | Nov 17, 2021 | The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege u... |
| CVE-2021-43337 | MEDIUM | 6.5 | 1.2% | Nov 17, 2021 | SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_scrip... |
| CVE-2021-3939 | HIGH | 7.8 | 0.3% | Nov 17, 2021 | Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallb... |
| CVE-2021-43012 | HIGH | 7.8 | 2.0% | Nov 16, 2021 | Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker ... |
| CVE-2021-43011 | HIGH | 7.8 | 2.0% | Nov 16, 2021 | Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now